Short answer: the DPDP Rules were notified on 13 November 2025. The Data Protection Board exists now. Consent manager provisions commence 12 November 2026. Almost everything else that imposes an obligation on your business — notice, consent, security safeguards, breach reporting, data principal rights — commences 12 May 2027.
Much of the DPDP material online was written while the Rules were still in draft, and reads as though nothing is settled. That is no longer the position. The dates below are the notified ones.
Where the law actually stands
| Phase | From | What commences |
|---|---|---|
| Immediate | 13 Nov 2025 | Rules 1, 2 and 17–21 — constitution and functioning of the Data Protection Board, appointments, inquiry procedure |
| 12 months | 12 Nov 2026 | Rule 4 — registration and obligations of consent managers |
| 18 months | 12 May 2027 | Rules 3, 5–16, 22, 23 — notice, consent, security safeguards, breach notification, children's data, Significant Data Fiduciary obligations, data principal rights, cross-border transfer |
Two implications people miss.
First, the Board is already operational. The institutional machinery was brought into force immediately, ahead of the obligations it will eventually enforce. The enforcement body exists before the duties bite.
Second, there is no grace period built into the design. The eighteen months is the transition window. A company that starts in early 2027 is not starting early.
As of this writing, roughly nine months remain before the substantive obligations commence.
Does it apply to us?
Almost certainly, if you process personal data in digital form.
There is no turnover threshold, no headcount threshold and no sector gate in the Act. If you hold an employee database, a customer or client list, vendor contact details, CCTV footage tied to identifiable people, or a website form that collects enquiries, you are processing digital personal data and you are a Data Fiduciary in respect of it.
What varies with size and risk is not whether the law applies but how much is proportionate — and whether the Central Government notifies you as a Significant Data Fiduciary, which adds a further layer.
For a professional services firm, a trading business or a small manufacturer, the practical scope is usually narrower than feared: employees, customers, vendors, and whatever a website collects. For anyone running a consumer app, a healthcare or education service, or a business built on customer data, it is considerably wider.
What full compliance requires
From 12 May 2027, the substantive obligations include:
- Notice — a clear, standalone statement to the individual of what personal data is collected, the purpose, and how to withdraw consent or complain. Notice buried inside general terms and conditions does not meet the standard.
- Consent — free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and as easy to withdraw as it was to give. Pre-ticked boxes and bundled consent do not qualify.
- Purpose limitation and data minimisation — collect only what is necessary for the stated purpose, and use it only for that purpose.
- Retention and erasure — delete personal data once the purpose is served, unless retention is required by another law. This is the obligation that most often collides with existing practice, because businesses tend to retain indefinitely by default.
- Reasonable security safeguards — an express obligation, and the one carrying the highest penalty ceiling.
- Breach notification — intimation to the Board and to affected data principals, with detailed particulars to follow within the short window the Rules prescribe (commonly cited as 72 hours). This requires a rehearsed process, not an intention.
- Data principal rights — access, correction, erasure, grievance redressal and nomination, each needing an actual mechanism and a named point of contact.
- Processor contracts — processing through a vendor must be under a valid contract, which means reviewing agreements with payroll providers, cloud services, CRM platforms and analytics tools.
- Children's data — verifiable parental consent, and no tracking, behavioural monitoring or targeted advertising directed at children.
The Significant Data Fiduciary layer
Where a company is notified as an SDF, Section 10 adds:
- a Data Protection Officer based in India, answerable to the board or governing body;
- an independent data auditor to evaluate compliance; and
- under Rule 13, a Data Protection Impact Assessment and audit once every twelve months, with the person carrying it out furnishing a report of significant observations to the Board.
Two honest observations about this. It applies only to entities actually notified as significant — it is not a size test a company can self-apply. And neither the Act nor the Rules as notified prescribe a professional qualification for the independent data auditor; what they stipulate is independence, which means an internal audit function cannot perform it. That leaves the role open in a way that will likely be clarified by practice or further rules.
The penalties
The Schedule sets maximum penalties, not fixed ones:
| Contravention | Ceiling |
|---|---|
| Failure to take reasonable security safeguards | ₹250 crore |
| Failure to notify a personal data breach | ₹200 crore |
| Contravention of children's data obligations | ₹200 crore |
| SDF failure on additional obligations | ₹150 crore |
| Other contraventions, including data principal duties and residuary | up to ₹50 crore |
The Board determines quantum having regard to the nature, gravity and duration of the contravention, the type of data affected, whether it was repetitive, and what remedial action was taken. Prompt remediation is expressly a mitigating factor — which is an argument for having a documented process before anything goes wrong, not after.
Headline ceilings make for alarming reading and are unlikely to be the reality for a mid-size company with a first, promptly remediated lapse. The more probable near-term consequences are commercial: enterprise customers, lenders and acquirers asking about DPDP posture in diligence long before the Board ever does.
What is worth doing in the window that remains
In rough order of usefulness:
- Build a data inventory. What personal data you hold, where it sits, why you have it, who can see it, and who you send it to. Nothing else can be done properly without this, and it takes longer than expected.
- Set retention periods. Decide how long each category is kept and on what basis. Indefinite retention is the most common gap and one of the more visible ones.
- Review vendor contracts. Anywhere personal data goes to a third party — payroll, cloud, CRM, marketing — needs contractual footing.
- Fix notice and consent flows on your website, app and onboarding forms, including a working withdrawal mechanism.
- Write down a breach response process and rehearse it once. A tight reporting window is not survivable improvised.
- Tighten access. Who can reach personal data, and does anyone hold access they no longer need.
Point 6 will look familiar to anyone who has been through controls testing — it is the same question asked in IT general controls work, applied to a different category of data. Companies that have already documented access, change and retention for audit purposes are a good part of the way toward the data inventory, and the two exercises are worth running together rather than twice.
A note on scope
DPDP work spans three disciplines: legal (notices, contracts, lawful basis), technical (security architecture, encryption, logging), and governance and assurance (inventory, controls, testing, audit). No single adviser covers all three, and anyone suggesting otherwise should be treated carefully.
What is offered here is the third — readiness assessment, data inventory, controls design and testing, and retention and access review — alongside internal financial controls and IS audit work, which draws on the same evidence. Legal drafting of privacy notices and contracts, and technical security implementation, sit with a lawyer and your IT or security provider respectively.
The DPDP Act 2023 and the Rules notified on 13 November 2025 are new and largely untested, and further rules, clarifications and Board practice can be expected. This note reflects the position as at the date above and should be confirmed against the current text before it is relied on.